Количество 301 801
Количество 301 801
GHSA-28r8-9g34-2x25
A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit this vulnerability by sending crafted HTTPS packets at a high and sustained rate. A successful exploit could allow the attacker to negatively affect the performance of the web UI. Cisco has addressed this vulnerability.
GHSA-28r8-6q2m-x9g4
The XD Forum (aka com.tapatalk.xdforumcomforum) application 3.9.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-28r7-8r62-w9hj
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44.
GHSA-28r6-jm5h-mrgg
Access control bypass in Beego
GHSA-28r4-58h5-m5rr
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
GHSA-28r2-q6m8-9hpx
HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion
GHSA-28qw-8jmg-32wx
Transient DOS when processing a NULL buffer while parsing WLAN vdev.
GHSA-28qr-hqrv-mhvr
libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.
GHSA-28qq-773c-49rf
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-28qp-wgp5-fp7m
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog.
GHSA-28qp-rcr7-xp4g
IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
GHSA-28qp-98vv-5xqx
The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecified vectors.
GHSA-28qp-8c7m-wc33
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
GHSA-28qm-wmpf-4vwh
The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.
GHSA-28qm-6v7q-2wqv
Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: FTS.
GHSA-28qj-gvxv-p5g9
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
GHSA-28qj-9gmx-6vpj
Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.
GHSA-28qj-36f6-4995
JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbitrary code via a crafted .js file, because unrecognized \ characters cause incorrect 0x00 characters in bytecode.literal data.
GHSA-28qh-hp2x-hp83
Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23173.
GHSA-28qh-gf6m-p898
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks allows PHP Local File Inclusion. This issue affects Gutenberg Blocks: from n/a through 3.3.1.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-28r8-9g34-2x25 A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit this vulnerability by sending crafted HTTPS packets at a high and sustained rate. A successful exploit could allow the attacker to negatively affect the performance of the web UI. Cisco has addressed this vulnerability. | 0% Низкий | больше 3 лет назад | ||
GHSA-28r8-6q2m-x9g4 The XD Forum (aka com.tapatalk.xdforumcomforum) application 3.9.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 3 лет назад | ||
GHSA-28r7-8r62-w9hj Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44. | 0% Низкий | 28 дней назад | ||
GHSA-28r6-jm5h-mrgg Access control bypass in Beego | 0% Низкий | больше 3 лет назад | ||
GHSA-28r4-58h5-m5rr In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-28r2-q6m8-9hpx HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion | CVSS3: 8.6 | 0% Низкий | больше 3 лет назад | |
GHSA-28qw-8jmg-32wx Transient DOS when processing a NULL buffer while parsing WLAN vdev. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-28qr-hqrv-mhvr libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006. | CVSS3: 9.1 | 0% Низкий | больше 3 лет назад | |
GHSA-28qq-773c-49rf SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-28qp-wgp5-fp7m Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog. | 0% Низкий | больше 3 лет назад | ||
GHSA-28qp-rcr7-xp4g IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | CVSS3: 5.4 | 0% Низкий | 8 месяцев назад | |
GHSA-28qp-98vv-5xqx The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecified vectors. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-28qp-8c7m-wc33 Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-28qm-wmpf-4vwh The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758. | 1% Низкий | больше 3 лет назад | ||
GHSA-28qm-6v7q-2wqv Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: FTS. | CVSS3: 6.5 | 5% Низкий | больше 3 лет назад | |
GHSA-28qj-gvxv-p5g9 Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting | CVSS3: 5 | 31% Средний | почти 2 года назад | |
GHSA-28qj-9gmx-6vpj Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT. | 3% Низкий | больше 3 лет назад | ||
GHSA-28qj-36f6-4995 JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbitrary code via a crafted .js file, because unrecognized \ characters cause incorrect 0x00 characters in bytecode.literal data. | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
GHSA-28qh-hp2x-hp83 Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23173. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-28qh-gf6m-p898 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks allows PHP Local File Inclusion. This issue affects Gutenberg Blocks: from n/a through 3.3.1. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу